BIOC Informational

Microsoft Office executes an unsigned process in a suspicious directory

Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: Visual Basic (T1059.005)
Indicator:

Process action type = execution AND target process path = *\appdata\* , *\programdata\* , *$recycle.bin* , *\temp\* , *\tmp\* , *\users*public\* AND process execution signature = Unsigned , Invalid Signature AND target process name != DriveForOffice.SyncHelper.exe AND CefSharp.BrowserSubprocess.exe AND Ifs.Fnd.Explorer.exe AND BAReportUpgradeUtilityLauncher.exe AND TSTPFLTK.exe AND 7zFM.exe AND notepad++.exe AND gpgme-w32spawn.exe AND python.exe AND target process name != F7-Zip*.exe AND pollev_browsers.exe AND SafeSendFileUploader-6.3.0.exe AND merrillhtmlfilter.exe AND dotnetbrowser-chromium32.exe AND fspublisher.exe AND validatehtml.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe , outlook.exe , visio.exe , winproj.exe , onenote.exe , cgo name = winword.exe , excel.exe , powerpnt.exe , outlook.exe , visio.exe , winproj.exe , onenote.exe , os parent name = winword.exe , excel.exe , powerpnt.exe , outlook.exe , visio.exe , winproj.exe , onenote.exe Host host os = windows

Preventable: yes